NIS2 management liability is the provision that gets cybersecurity budgets approved, and it is the one most summaries reduce to a single vague sentence about “management accountability”.
The Directive is more specific than that. It places three named duties on management bodies, requires them personally to be trained, and — for essential entities — puts a temporary ban on holding managerial office in the enforcement toolkit.
What NIS2 management liability means in Article 20

Article 20(1) requires Member States to ensure that the management bodies of essential and important entities:
- approve the cybersecurity risk-management measures taken to comply with Article 21;
- oversee its implementation; and
- can be held liable for infringements by the entity of that Article.
Three verbs, three different obligations, and together they are what NIS2 management liability rests on. Approve is a decision that has to be recorded. Oversee is a continuing duty that survives the approval — a management body that signed off a programme in 2025 and never asked about it again has approved but not overseen. And liable is the consequence attaching to both.
Note the scope: this applies to essential and important entities alike. The distinction between the two categories changes the supervisory regime, not these governance duties.
NIS2 management liability includes a personal training duty
Article 20(2) is the part that surprises boards. Member States shall ensure that members of the management bodies are required to follow training — so they gain sufficient knowledge and skills to identify risks and assess cybersecurity risk-management practices and their impact on the services the entity provides.
Two things follow.
It is required for them, and encouraged for everyone else. The Directive requires training for management bodies and separately says Member States shall encourage entities to offer similar training to employees on a regular basis. The mandatory limb points at the top of the organisation.
The purpose is stated, which sets the standard. The training exists so directors can identify risks and assess practices — that is, form their own view rather than accept a report. An hour of generic awareness content does not obviously produce that capability, and the wording gives a supervisor something concrete to probe.
The sanction that makes NIS2 management liability real
Article 32(5) applies where an essential entity has been given a deadline to remedy deficiencies and has not met it. Competent authorities then have the power to:
- suspend temporarily — or ask a certification or authorisation body, court or tribunal to suspend — a certification or authorisation covering part or all of the entity’s relevant services or activities; and
- request that the relevant bodies, courts or tribunals prohibit temporarily any natural person responsible for discharging managerial responsibilities at chief executive officer or legal representative level from exercising managerial functions in that entity.
That second power is the part of NIS2 management liability worth reading aloud to a board. It is not a fine paid by the company. It removes a named individual from managerial functions for a period.
It applies to essential entities. Important entities face a different enforcement regime, and conflating the two overstates the position for a large part of the market — which is worth getting right rather than using as a scare tactic.
Individual responsibility under Article 32(6)
Separately, Article 32(6) requires Member States to ensure that any natural person who is responsible for, or acts as legal representative of, an essential entity — on the basis of power to represent it, authority to take decisions on its behalf, or authority to exercise control of it — has the power to ensure its compliance with the Directive. And that it is possible to hold such persons liable for breach of their duties to ensure compliance.
The first half is easy to skim past and is the more useful one internally: the person carrying the duty must actually have the power to discharge it. A named accountable executive without budget, authority or access to the risk picture is a governance defect the Directive implicitly identifies.
Both Article 20(1) and Article 32(6) carve out national liability rules for public administration entities, public servants and elected or appointed officials.
What this means in practice
NIS2 management liability turns three ordinary governance habits into evidence you need to be able to produce.
- A recorded approval of the Article 21 measures, by the management body, with a date and a version of what was approved.
- Evidence of oversight between approvals — reporting cadence, what was escalated, what the body asked for and what changed as a result.
- Training records for individual directors, not an organisation-wide completion statistic.
- A named accountable person with actual authority, documented.
- A remediation tracker, because the Article 32(5) powers bite on missed deadlines rather than on the original deficiency.
That last point reframes the risk. The trigger for the harshest measures is not having a weakness — it is being told to fix it and not doing so in time.
How NIS2 management liability connects
| Area | Connection |
|---|---|
| NIS2 requirements | Article 21 is what management approves and oversees — including the supply chain measures in 21(2)(d) |
| NIS2 penalties | The financial side. Article 32(5) sits alongside it and reaches individuals rather than balance sheets |
| Who NIS2 applies to | Essential or important matters here: the Article 32(5) powers are an essential-entity regime |
| ISO 27001 | Clause 5 leadership, management review and the audit programme produce exactly the approval and oversight evidence Article 20 expects |
Where to start with NIS2 management liability
- Put the Article 21 measures to the management body for formal approval, and minute it properly.
- Set an oversight cadence with defined reporting, so oversight is demonstrable between approvals.
- Book director-level training aimed at identifying risks and assessing practices, and keep individual records.
- Confirm the accountable person has the power to ensure compliance — budget, authority, information.
- Track remediation deadlines hardest, since that is what triggers the severest measures.
- Check your national transposition, because NIS2 is a directive and liability rules are implemented domestically.
This guide reflects Directive (EU) 2022/2555 as published on EUR-Lex, read at 16 August 2026. NIS2 is transposed into national law — the applicable liability regime is your Member State’s.
The NIS2 Toolkit provides 75+ editable templates covering the Article 21 measures, the governance and approval records, the training and awareness artefacts and the incident and remediation documentation.